UbuntuUpdates.org

Package "ncurses-bin"

Name: ncurses-bin

Description:

terminal-related programs and man pages

Latest version: 6.1-1ubuntu1.18.04.1
Release: bionic (18.04)
Level: security
Repository: main
Head package: ncurses
Homepage: https://invisible-island.net/ncurses/

Links


Download "ncurses-bin"


Other versions of "ncurses-bin" in Bionic

Repository Area Version
base main 6.1-1ubuntu1
updates main 6.1-1ubuntu1.18.04.1

Changelog

Version: 6.1-1ubuntu1.18.04.1 2023-05-23 12:06:57 UTC

  ncurses (6.1-1ubuntu1.18.04.1) bionic-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in the _nc_find_entry function
    - debian/patches/CVE-2019-17594.patch: check for invalid hashcode in
      _nc_find_type_entry and _nc_find_entry.
    - CVE-2019-17594.patch
  * SECURITY UPDATE: heap buffer overflow in the fmt_entry function
    - debian/patches/CVE-2019-17595.patch: check for missing character after
      backslash in fmt_entry.
    - CVE-2019-17595
  * SECURITY UPDATE: heap buffer overflow in the _nc_captoinfo function
    - debian/patches/CVE-2021-39537.patch: add a check for end-of-string in
      cvtchar to handle a malformed string in infotocap.
    - CVE-2021-39537
  * SECURITY UPDATE: out-of-bounds read in the convert_strings function
    - debian/patches/CVE-2022-29458.patch:add a limit-check to guard against
      corrupt terminfo data.
    - CVE-2022-29458
  * SECURITY UPDATE: memory corruption when processing malformed terminfo data
    entries loaded by setuid/setgid programs
    - debian/patches/CVE-2023-29491-mitigation.patch: change the
      --disable-root-environ configure option behavior.
    - debian/rules: set --disable-root-environ in configuration options.
    - debian/libtinfo5.symbols: add _nc_env_access to symbols files.
    - CVE-2023-29491
  * debian/patches/fix-off-by-one-loop-convert-strings.patch: correct an
    off-by-one loop-limit in convert_strings function.
  * debian/patches/fix-tic-infloop.diff: modify tic to exit if it cannot
    remove a conflicting name.
  * debian/patches/fix-write_it.diff: check for missing character after
    backslash in write_it.

 -- Camila Camargo de Matos <email address hidden> Tue, 16 May 2023 15:54:45 -0300

CVE-2019-17594 There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17595 There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2021-39537 An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
CVE-2022-29458 ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo libra
CVE-2023-29491 ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data



About   -   Send Feedback to @ubuntu_updates